Two-Factor Authentication
409
NETGEAR ProSAFE VPN Firewall FVS318G v2
• The PIN to access your account is something you know.
• The ATM card is so
mething you possess.
You must use both of these factors to gain access to your bank account. Similar t
o the way
ATM cards work, access to the corporate networks and data can also be strengthened using
a combination of multiple factors such as a PIN and a token (hardware or software) to
validate the users and reduce the incidence of online identity theft.
NETGEAR Two-Factor Authentication Solutions
NETGEAR implements two two-factor authentication solutions from WiKID. WiKID is the
software-based token solution. So instead of using only Windows Active Directory or LDAP
as the authentication server, administrators now can use WiKID to perform two-factor
authentication on NETGEAR VPN firewall products.
The WiKID solution is based on a request-response architecture where a
one-time passcode
(OTP), which is time-synchronized with the authentication server, is generated and sent to
the user after the validity of a user credential is confirmed by the server.
The request-response architecture is capable of self-service initialization
by end users,
dramatically reducing implementation and maintenance costs.
Here is an example of how WiKID works:
To use WiKID (for end users):
1. Launch the WiKID token software, enter the PIN that was provided
(something the user
knows), and click the Continue button to receive the OTP from the WiKID
authentication server: